StackRadar

CVE-2026-54272

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.1116
OSV records
GHSA-22jq-vg5j-6vgg

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.2.1

Open the chart page →

8,303
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.2.1

Open the chart page →

435
miot-dashboard-servermicroboxlabs0.1.11 of 1See more

miot-dashboard-server microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
ip-address@10.2.0
10.2.1

Open the chart page →

237
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.1

Open the chart page →

10,603
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.2.1

Open the chart page →

1,759
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.1

Open the chart page →

1,038
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.2.1

Open the chart page →

595
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.2.1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.2.1

Open the chart page →

4,660
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.1

Open the chart page →

1,038
portalplatform-mesh-portal0.19.41 of 1See more

portal platform-mesh-portal 0.19.4

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
ip-address@10.2.0
10.2.1

Open the chart page →

301
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.2.1

Open the chart page →

276
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.1

Open the chart page →

9,047
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.2.1

Open the chart page →

30,219
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.2.1

Open the chart page →

3,707
rybbitrybbit-helm1.3.02 of 7See more

rybbit rybbit-helm 1.3.0

2 of the 7 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.2.1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.2.1

Open the chart page →

5,819
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.2.1

Open the chart page →

387
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.1

Open the chart page →

1,991
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.1

Open the chart page →

2,638
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.1

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.1

Open the chart page →

919
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.2.1

Open the chart page →

9,556
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.2.1

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.2.1

Open the chart page →

5,550
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.2.1

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.2.1

Open the chart page →

1,961
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.1

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@10.2.0
10.2.1

Open the chart page →

5,459

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.2.1
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.2.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.2.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.2.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.2.0
10.2.1
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.2.1
1
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.2.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.2.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.2.1
1
oneuptime/nginx:release6da7de4fc0f3
ip-address@10.2.0
10.2.1
1
oneuptime/probe:release6b2d98713711
ip-address@10.2.0
10.2.1
1
oneuptime/runner:release4accc516d800
ip-address@10.2.0
10.2.1
1
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.2.0
10.2.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.2.1
1
penpotapp/exporter:2.17.272a8061e8806
ip-address@10.2.0
10.2.1
1
penpotapp/mcp:2.17.284f3f07ead11
ip-address@10.2.0
10.2.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.2.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.2.0
10.2.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.2.0
10.2.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.2.0
10.2.1
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.2.1
1
shieldsio/shields:nextfa194b446e42
ip-address@10.2.0
10.2.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.2.0
10.2.1
1
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.2.1
1
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.2.1
1
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.2.1
1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.2.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.2.0
10.2.1
1
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.2.1
1
veecode/devportalc443520aebf7
ip-address@10.2.0
10.2.1
1
wsjbr/duplistatus:1.4.25e594f5f09f6
ip-address@10.2.0
10.2.1
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
ip-address@10.2.0
10.2.1
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.2.1
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.2.1
1
ghcr.io/backstage/backstage:latest792e262ea504
ip-address@10.2.0
10.2.1
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.2.1
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.2.1
1
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.2.1
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.2.1
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.2.1
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.2.1
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.2.1
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.2.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.2.1
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.2.1
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.2.1
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
ip-address@10.2.0
10.2.1
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.2.1
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.2.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.